|
OpenBB contains a flaw that allows a remote attacker to read arbitrary private messages. The issue is due to the software not properly verifying user ID or session ID when displaying private messages. If an attacker provides a specially crafted URL with the ID of an arbitrary message, the system will display it.
|